Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | eap-radius: use IKE_SA unique id instead of peer identity to manage virtual IPs | Martin Willi | 2013-05-06 | 3 | -34/+100 | |
| | | | | Fixes some corner cases if multiple tunnels use the same peer identity. | |||||
* | Don't unset IKE_SA on bus before we released virtual IPs and attributes | Martin Willi | 2013-05-06 | 1 | -10/+8 | |
| | ||||||
* | New Android release after adding AES-GCM, IPv6-in-IPv4 and using kernel-netlink | Tobias Brunner | 2013-05-03 | 1 | -2/+2 | |
| | | | | | | | | libipsec now supports AES-GCM, IPv6 tunnels over IPv4 are supported, native x86 libraries are built (requires a new Vstr build script). Also, the existing kernel-netlink plugin now provides the kernel-net implementation, which should be more stable in case multiple interfaces are up and have IP addresses installed on them. | |||||
* | libipsec: Fix memory leak in event relay | Tobias Brunner | 2013-05-03 | 1 | -0/+1 | |
| | ||||||
* | android: Use stronger ESP proposal including AES-GCM | Tobias Brunner | 2013-05-03 | 1 | -0/+6 | |
| | ||||||
* | libipsec: Add support for AES-GCM | Tobias Brunner | 2013-05-03 | 1 | -3/+45 | |
| | ||||||
* | libipsec: Wrap traditional algorithms in AEAD wrapper | Tobias Brunner | 2013-05-03 | 3 | -110/+91 | |
| | ||||||
* | android: Remove unused methods on NetworkManager/network_manager_t | Tobias Brunner | 2013-05-03 | 3 | -177/+1 | |
| | ||||||
* | android: Ignore interface 'lo' | Tobias Brunner | 2013-05-03 | 1 | -2/+4 | |
| | | | | | Android adds a default route via 'lo' if no connectivity is available causing charon to send packets via lo and triggering DPD. | |||||
* | android: Repurpose android-net to simply handle connectivity events | Tobias Brunner | 2013-05-03 | 3 | -59/+34 | |
| | | | | | | Using the events by NetworkManager/ConnectivityManager to trigger roam events instead of the events generated by the kernel-netlink plugin the noise level is much lower. | |||||
* | kernel-netlink: Add an option to disable roam events | Tobias Brunner | 2013-05-03 | 2 | -1/+16 | |
| | ||||||
* | android: Replace android-net plugin with kernel-netlink | Tobias Brunner | 2013-05-03 | 2 | -3/+8 | |
| | | | | | Virtual IPs are not handled by the kernel-netlink plugin and tun devices are ignored. | |||||
* | android: Set strongswan.conf options before initializing other libraries | Tobias Brunner | 2013-05-03 | 1 | -36/+44 | |
| | ||||||
* | kernel-netlink: Define defaults for routing table and prio | Tobias Brunner | 2013-05-03 | 1 | -0/+8 | |
| | ||||||
* | openssl: Define a default for FIPS_MODE | Tobias Brunner | 2013-05-03 | 1 | -0/+4 | |
| | ||||||
* | In memwipe_check(), don't put magic on stack when calling do_magic() | Martin Willi | 2013-05-03 | 1 | -3/+3 | |
| | | | | Otherwise the magic might be on the stack while checking it. | |||||
* | Dump stack if memwipe() check fails | Martin Willi | 2013-05-03 | 1 | -3/+19 | |
| | ||||||
* | Use attest database in tnc/tnccs-20-os scenario5.0.4 | Andreas Steffen | 2013-04-21 | 6 | -2/+268 | |
| | ||||||
* | fixed a 64bit time_t issue | Andreas Steffen | 2013-04-21 | 1 | -3/+4 | |
| | ||||||
* | destroy SQL query | Andreas Steffen | 2013-04-21 | 1 | -0/+1 | |
| | ||||||
* | Keep last AR ID | Andreas Steffen | 2013-04-21 | 1 | -0/+2 | |
| | ||||||
* | Added use of openssl-fips library to NEWS | Andreas Steffen | 2013-04-19 | 1 | -0/+2 | |
| | ||||||
* | check for successful activation of FIPS mode | Andreas Steffen | 2013-04-19 | 1 | -1/+4 | |
| | ||||||
* | install FIPS-aware OpenSSL Debian packages | Andreas Steffen | 2013-04-19 | 1 | -18/+5 | |
| | ||||||
* | Added openssl-ikev2/rw-cpa scenario | Andreas Steffen | 2013-04-19 | 29 | -0/+472 | |
| | ||||||
* | build openssl-fips in KVM root-image | Andreas Steffen | 2013-04-19 | 5 | -0/+49 | |
| | ||||||
* | fixed typo | Andreas Steffen | 2013-04-19 | 1 | -1/+1 | |
| | ||||||
* | During libstrongswan initialization, check if memwipe() works as expected | Martin Willi | 2013-04-18 | 1 | -1/+51 | |
| | ||||||
* | added libstrongswan.plugins.openssl.fips_mode to man page | Andreas Steffen | 2013-04-16 | 1 | -0/+3 | |
| | ||||||
* | support of OpenSSL FIPS-140-2 library | Andreas Steffen | 2013-04-16 | 3 | -1/+21 | |
| | ||||||
* | build soup plugin in KVM test environment | Andreas Steffen | 2013-04-15 | 2 | -1/+2 | |
| | ||||||
* | disable reauth, too | Andreas Steffen | 2013-04-15 | 1 | -1/+2 | |
| | ||||||
* | Fix checksum calculation with DESTDIR installations | Tobias Brunner | 2013-04-15 | 1 | -1/+1 | |
| | ||||||
* | version bump to 5.0.4 | Andreas Steffen | 2013-04-14 | 2 | -1/+21 | |
| | ||||||
* | Added charon.initiator_only option which causes charon to ignore IKE ↵ | Andreas Steffen | 2013-04-14 | 24 | -2/+277 | |
| | | | | initiation requests by peers | |||||
* | Allow SHA1_Init()/SHA1_Update() to fail if OpenSSL version >= 1.0 | Martin Willi | 2013-04-10 | 1 | -0/+14 | |
| | ||||||
* | Check RSA_public_decrypt() length before constructing and comparing a chunk | Martin Willi | 2013-04-10 | 1 | -7/+10 | |
| | | | | | If decryption fails, it returns -1. chunk_equals() should catch that error, but be more explicit in error checking. | |||||
* | RSA_check_key() may return -1 if it fails | Martin Willi | 2013-04-10 | 1 | -2/+2 | |
| | ||||||
* | RAND_bytes/RAND_pseudo_bytes returns -1 if it is not supported by RAND method | Martin Willi | 2013-04-10 | 1 | -1/+1 | |
| | ||||||
* | Check return value of ECDSA_Verify() correctly | Martin Willi | 2013-04-10 | 1 | -1/+1 | |
| | ||||||
* | eap-radius: Add an option to exclude ports from Called/Calling-Station-Id | Martin Willi | 2013-04-10 | 2 | -9/+37 | |
| | ||||||
* | version bump to 5.0.4dr1 | Andreas Steffen | 2013-04-09 | 1 | -1/+1 | |
| | ||||||
* | fixed another printf statement | Andreas Steffen | 2013-04-09 | 1 | -3/+1 | |
| | ||||||
* | fixed printf statements | Andreas Steffen | 2013-04-08 | 2 | -10/+29 | |
| | ||||||
* | emit a single assig_vips bus message for all VIPs | Andreas Steffen | 2013-04-06 | 8 | -62/+57 | |
| | ||||||
* | ifmap plugin subscribes to assing_vip bus signal | Andreas Steffen | 2013-04-06 | 7 | -2/+135 | |
| | ||||||
* | Added missing sasl Doxygen group | Tobias Brunner | 2013-04-05 | 1 | -0/+3 | |
| | ||||||
* | unity: Check IKE_SA in only after enumerating virtual IPs | Tobias Brunner | 2013-04-05 | 1 | -2/+1 | |
| | ||||||
* | fixed configure options5.0.3 | Andreas Steffen | 2013-04-04 | 1 | -0/+2 | |
| | ||||||
* | cleaned up XML code in tnccs-11 plugin | Andreas Steffen | 2013-04-04 | 13 | -92/+95 | |
| |